All jobs
UnionBank of the Philippines

Cybersecurity Analyst

UnionBank of the Philippines ·

Pasig · Remote25 yrs · Full-time0 applied1 viewsPosted 17d ago

Monitor, investigate and respond to security threats across client environments while helping strengthen day-to-day cyber defence.

About the role

SentinelForge Security Services is looking for a Cybersecurity Analyst to join its Security Operations team. This role is suited to someone who enjoys investigating alerts, connecting technical clues and understanding how attacks actually unfold. You will work with SIEM, endpoint and network-security data, support incident response, and help improve detection rules and operating procedures across multiple enterprise environments.

What you'll do

  • Monitor SIEM, EDR and network-security alerts and investigate suspicious activity.
  • Triage incidents by analysing logs, endpoints, user activity, IPs, domains and network indicators.
  • Escalate confirmed threats with clear evidence, impact assessment and recommended containment steps.
  • Support phishing, malware, account-compromise and unauthorized-access investigations.
  • Tune detection rules and reduce false positives based on recurring alert patterns.
  • Perform basic threat hunting using known indicators, attacker techniques and MITRE ATT&CK; mappings.
  • Assist with vulnerability-review activities and track remediation with infrastructure teams.
  • Document incidents, investigation timelines and lessons learned for internal and client reviews.

What we're looking for

  • 2-5 years of experience in SOC, cybersecurity operations, incident response or security monitoring.
  • Hands-on experience with a SIEM platform such as Splunk, Microsoft Sentinel, QRadar or similar.
  • Good understanding of TCP/IP, DNS, HTTP/HTTPS, firewalls, VPNs and common network-security concepts.
  • Experience analysing Windows and Linux logs, endpoint events and authentication activity.
  • Familiarity with EDR, IDS/IPS, vulnerability scanners and common attack techniques.
  • Ability to investigate methodically and communicate findings clearly during active incidents.
  • Security certifications such as Security+, CEH, SC-200 or equivalent are useful but not mandatory.

Benefits

  • Shift allowance for rotational SOC coverage, where applicable.
  • Certification reimbursement for approved cybersecurity credentials.
  • Hands-on access to enterprise SIEM, EDR and threat-intelligence platforms.
  • Quarterly internal red-team / blue-team simulation days for practical learning.
  • Compensatory time off for approved after-hours incident-response support.

Skills

SIEMSOC OperationsIncident ResponseEDRIDS/IPSNetwork SecurityLog AnalysisThreat DetectionVulnerability ManagementTCP/IPWindows SecurityLinuxMITRE ATT&CKSplunkMicrosoft Sentinel